Back to skill

Security audit

Work Productivity Self Improving Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but it does not request sensitive access or perform hidden actions.

Installers should be aware this skill may activate for generic productivity or self-improvement wording. It appears safe as a workflow helper, but users may prefer narrower trigger terms or explicit invocation if they want to avoid irrelevant routing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentences are broad, repetitive, and use generic terms like 'help me' and 'practical workflow,' which can cause the skill to activate for loosely related requests. In an agent ecosystem, ambiguous invocation increases the chance of unintended routing, context confusion, or the wrong workflow being applied to user tasks, reducing reliability and potentially causing unsafe automation in adjacent contexts.

Vague Triggers

High
Confidence
89% confidence
Finding
The trigger phrases are broad enough to match generic terms like 'self', 'improving', 'proactive', and 'bug fix', which can cause the skill to activate in contexts the user did not intend. In an agent ecosystem, overly permissive activation can route unrelated requests into this skill, creating unsafe or unreliable behavior and increasing the chance of unintended autonomous workflow suggestions.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes extremely generic terms such as 'self', 'improving', 'proactive', 'learning', and 'organizing', which are common in normal user requests and can cause this skill to activate unintentionally. In an agent environment, overbroad activation can misroute tasks, override more appropriate skills, and create unsafe or unreliable behavior through prompt collision and scope confusion.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation description says to use the skill when a user asks for broad categories like 'work-productivity', 'self', 'improving', or 'proactive', which does not clearly delimit when the skill should or should not run. This ambiguity increases accidental invocation risk, especially because the skill is framed as adaptable and adjacent to many workflows, making routing errors more likely than intended use.

Vague Triggers

High
Confidence
96% confidence
Finding
触发关键词包含“self”“improving”“proactive”等高度常见且语义宽泛的词,容易在与该技能无关的普通对话中被误触发。误调用会把用户带入不相关的工作流,增加错误建议、上下文偏移和权限范围扩大风险,尤其在自动路由或多技能环境中更危险。

Vague Triggers

Medium
Confidence
91% confidence
Finding
技能描述将适用范围写得过宽,例如只要用户提出若干泛化主题或“需要实用流程、产物、检查清单、分析或实现支持”即可使用,缺少清晰边界。这会导致路由器或代理在大量普通生产力请求中选择该技能,造成误用、错误优先级和不恰当的自主行为倾向。

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt contains broad, natural-language trigger terms such as "help me" and general productivity phrasing that can cause unintended or implicit invocation in unrelated conversations. Because implicit invocation is enabled, this increases the chance the skill activates outside its intended scope, potentially injecting its workflow behavior or guidance into benign user interactions.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are extremely broad and include common words like 'help', 'practical workflow', 'self', 'improving', and 'proactive', which can cause the skill to activate for many unrelated user requests. In an agent ecosystem, unintended invocation can route users into the wrong workflow, cause irrelevant automation, and create safety issues if downstream actions are taken based on a mistaken match.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.